Helix is a financially motivated cybercriminal extortion group focused on stealing enterprise cloud data and demanding payment to prevent its disclosure. Microsoft tracks actors operating under the Helix banner as Storm-3032, a cluster that splintered from BlackFile. Helix is also associated with the broader UNC6671 activity cluster and shares phishing infrastructure and techniques with the Redact, Pink, and Falcon extortion brands. These relationships do not establish that all brands represent a single actor. Helix targets U.S. organizations, including transportation and logistics companies, financial institutions, private equity firms, energy businesses, and professional-services organizations. It operates a data leak site to publicize victims and expose stolen information. Uber Freight disclosed unauthorized access to its systems after Helix listed the company, although the authenticity and volume of the purported leaked data were not independently confirmed. Its intrusion playbook centers on cloud identity compromise. Operators impersonate corporate IT help desks through telephone calls and messages, using urgent passkey, multifactor authentication, or single sign-on update pretexts. Adversary-in-the-middle phishing captures credentials and authenticated session tokens, while device-code phishing induces victims to authorize attacker-controlled clients. Operators establish persistence by registering authentication methods under their control. Following compromise, attackers use Microsoft Graph and automated scripts to enumerate tenant identities, privileges, applications, and accessible repositories, then collect documents and email from SharePoint Online, OneDrive for Business, and Exchange Online. Collection can be paced over hours or days to evade volume-based detection, with proxy infrastructure supporting account access and data theft. Helix's established extortion model relies on stolen data and threats of publication; encryption-based ransomware deployment is not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a sibling brand of FALCON in a table describing adversary-in-the-middle phishing.
Named as an example of groups compromising Microsoft 365 accounts through phishing and vishing, then abusing identities, tokens, and Microsoft Graph to automate data exfiltration and extortion. No separate HELIX-specific campaign details are provided.
An extortion group linked to former BlackFile members and associated in this reporting with Storm-3032.
The extortion operation operated by Storm-3032.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.